lead-qualification

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted lead parameters (name, company, email) and instructs the agent to perform external searches and web fetches against these targets.
  • Ingestion points: Input parameters (<name> <email or company>) and pasted lists of leads inside SKILL.md steps 1 and 2.
  • Boundary markers: Absent. There are no delimiters or instruction-isolation markers enforced on the parsed lead tokens or fetched webpage text.
  • Capability inventory: The skill leverages the Bash tool as defined in the allowed-tools configuration, which represents an executable system capability tier.
  • Sanitization: No sanitization, escaping, or strict text filtering is specified before evaluating fetched data from external sites.
  • [COMMAND_EXECUTION]: The skill specifies the Bash tool within its allowed-tools frontmatter section. While no dangerous scripts or explicit shell payloads are present in the static markdown instructions, assigning shell execution privileges creates a surface that must be coupled with human review checkpoints if external untrusted context is parsed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:39 PM